Security & honesty
The rules we cannot break
These are not policies. They are how the product is built, and each one is checked by the test suite that gates every change.
Derived verdicts
No control anywhere lets a human type a verdict. Only the approvals, overrides and notices around one are written, each with a name on it.
No autonomous email
The product sends a customer nothing on its own. Every notice and every reminder is one person pressing once, recorded with who and when.
Silence never concludes
An expired window is recorded as a date fact. Concluding anything from it is a named human act.
Append-only audit trail
Approvals, overrides, sends and their refusals, key rotations, offboardings and merges land in an audit table that database triggers keep append-only.
Every key has a way back
Portal links and report tokens can be rotated and revoked. Following a portal link spends it: the address a customer sits on carries no token.
Evidence is dated
Transfer approvals carry expiry dates. DPF checks record when somebody looked, and go stale on a calendar the register enforces.
Identity stays yours
The register holds tool identity and aliases. Sister products read over keyed APIs and keep ids, never copies of your data.
See it against your own stack
Bring one product and one contract. The first verdicts take an afternoon.